Security Scan Report: bx.wsapbfy.net

Submitted: Sep 15, 2026, 12:50:04 PMCompleted: Sep 15, 2026, 12:50:29 PMpubliccompleted

AI Security Verdict

High Risk

Confidence: 90%

8
Risk Score

Confirmed Microsoft-branded phishing kit: 'Document Access Required' email gate on an unrelated, unranked domain that harvests the visitor's email to forward to a next-stage phishing URL.

Risk Factors (5)
Known malicious phishing kit identified by analyst-vetted roster and YARA rule
Impersonation of Microsoft brand on a non-Microsoft domain
Email-harvesting form gating access to a fake 'requested document'
Deceptive social engineering pretext (document access verification, fake device/location panel)
Domain unranked in Cisco Umbrella with only ~92 days of age
Domain age information unavailable

Details

Page Title

Document Access Verification

Scan Type

public

Domain Name Analysis

Within the network infrastructure generic top-level domain (.net), 'bx.wsapbfy.net' is registered with subdomain 'bx'. Count 7 characters in 'wsapbfy' containing 1 vowel alongside six consonants. Word splitting yields four words: w, sap, b, fy. Average segment length settles at 1.5 characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of https://bx.wsapbfy.net/leona.denesha/tessere.html

Page Load Overview

5.73s
Total Load Time
23 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:80%
Script:Latin
Direction:ltr

Detection Details

HTML Lang Attribute:en
Text Length:384 chars
Detector Agreement:100%

Website Classification

Primary Category

technology software69% confidence
Type: static
Method: ml+structural+ocr_tiebreaker

All Detected Categories

technology software
69%
documentation technical
43%
corporate business
41%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
213.107.246.44Azure · CLOUDUnited States
AS8075Microsoft Corporation
1162.254.24.67United States
AS54548IONOS Cloud Inc.
1184.30.220.140Akamai · CDNFrankfurt am Main, Hesse, Germany
AS16625Akamai Technologies, Inc.
43--

Detected Technologies1

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T101221CB23249006926A3CCF730531749B0B18651FD02C59AF5A5FB668BD7E470E32F8B

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

192:V+9RZdHUqPl4ZsaEjA19fGxzoz1ULHqnnH3ADkTeYNpExTzIbaCwiRP78nj:LsaEk19fczi1ULHqnnH3UkTeYNpExHIw

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:10305:WiCJUQFBAR44ERDfkJEdYAKJdRAAqQMmNiEMAKhrjBTQJEACJCcUwQIYJiAsWRoQh4RIQGC3JTQACiFCggM4SiMg5iMDu0AC

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffe7e7e7e7ffff
Perceptual Hash:e6cc992366993366
Difference Hash:00000c0c0c4d0008
Wavelet Hash:3c242424e4e4e0f0
Color Hash:#e0a46c

Other Hashes

Crop Resistant:00000c0c0c4d0008

Scan History

Scan history not available

Unable to load historical scan data